Session
Evading Detection with Dynamic AI Mimicry
Threat actors are increasingly leveraging large language models (LLMs) to create adaptive malware that evades traditional detection methods. This research introduces a novel AI-assisted malware prototype that enhances stealth by intelligently adapting to target environments. Our cloud provider discovery framework enumerates systems for evidence of AWS, Azure, or GCP usage, enabling malware to select the most appropriate cloud service for command and control operations. We demonstrate this capability through a novel agentic framework for macOS that dynamically leverages enterprise cloud AI services (AWS Bedrock, Azure OpenAI, or GCP Vertex AI) to blend malicious traffic with legitimate enterprise activity. This approach significantly complicates detection by mimicking authorized cloud usage patterns. We provide actionable defensive recommendations including comprehensive AI service monitoring, strict access controls, and prohibition of unauthorized AI platforms, while outlining future research into embedded models and novel detection methodologies.
Darin Smith
Leader, Security Research, Cisco Talos
Walnut Creek, California, United States
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top